Description
SurrealDB versions before 2.2.2 contain an uncaught exception vulnerability in the net module that allows authenticated users to crash the database. Attackers can send crafted HTTP queries containing null bytes to the /sql endpoint, causing an unhandled exception that crashes the SurrealDB instance and any dependent applications.
Published: 2026-07-18
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An uncaught exception in SurrealDB's net module lets an authenticated user crash the database by sending a crafted HTTP contains null bytes. The exception propagates without handling, terminating the SurrealDB instance and any applications that depend on it, resulting in a denial of service and potentially taking the entire database offline.

Affected Systems

This flaw affects SurrealDB products from the SurrealDB vendor. All builds released before version 2.2.2 are vulnerable, including 2.2.1 and earlier releases. The vulnerability can only be exploited by users who have valid authentication credentials against the database.

Risk and Exploitability

The CVSS base score of 7.1 indicates a moderate to high impact, while the EPSS score of less than 1% shows a very low likelihood of widespread exploitation. The flaw is not listed in CISA's KEV catalog. Attackers would need legitimate credentials and network access to the /sql endpoint; once authenticated, the unhandled exception causes the service to crash, leading to a denial of service.

Generated by OpenCVE AI on July 30, 2026 at 23:04 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade SurrealDB to version 2.2.2 or later to apply the vendor‑provided fix.
  • If an update cannot be performed immediately, block or for unauthenticated or unauthorised traffic using network firewalls or reverse‑proxy rules.
  • Configure request validation or input sanitisation at the proxy level to reject queries that contain null bytes before they reach the database.

Generated by OpenCVE AI on July 30, 2026 at 23:04 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Jul 2026 02:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:surrealdb:surrealdb:*:*:*:*:*:*:*:*

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Surrealdb
Surrealdb surrealdb
Vendors & Products Surrealdb
Surrealdb surrealdb

Mon, 20 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 18 Jul 2026 13:45:00 +0000

Type Values Removed Values Added
Description SurrealDB versions before 2.2.2 contain an uncaught exception vulnerability in the net module that allows authenticated users to crash the database. Attackers can send crafted HTTP queries containing null bytes to the /sql endpoint, causing an unhandled exception that crashes the SurrealDB instance and any dependent applications.
Title SurrealDB before 2.2.2 Denial of Service via /sql endpoint
Weaknesses CWE-248
References
Metrics cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Surrealdb Surrealdb
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-07-28T01:48:15.557Z

Reserved: 2026-07-16T12:14:41.770Z

Link: CVE-2025-71391

cve-icon Vulnrichment

Updated: 2026-07-20T15:13:14.608Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-30T23:15:06Z

Weaknesses